CVE-2026-5305Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-25: 2Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 206-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Unauthenticated stored XSS in Email Address Encoder email replacement (CVE-2026-5305) A stored cross-site scripting flaw exists in the Email Address Encoder WordPress plugin and its email-encoder-premium counterpart due to unsafe handling of email replacement output. The root cause is improper input validation/output encoding, allowing attacker-controlled content to be persisted and rendered as script. An attacker can exploit this remotely without authentication by injecting crafted payloads that get stored during the plugin’s email replacement process and later served to visitors/admins. Impact includes arbitrary JavaScript execution in victims’ browsers, leading to admin session hijack, malicious redirects, and potential site takeover via chained admin actions. 👉 Affected: Email Address Encoder < 1.0.25; email-encoder-premium < 0.3.12 | Upgrade to Email Address Encoder 1.0.25 / email-encoder-premium 0.3.12

    Post summary

    The post announces a stored XSS flaw in the Email Address Encoder WordPress plugin (CVE-2026-5305), with technical details indicating unauthenticated attack vectors and recommended patches, but no PoC, exploit tool, or active exploitation evidence.

    0000069
    228 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5305 Stored XSS Vulnerability in Email Address Encoder WordPress Plugin Before 1.0.25 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5305

    Post summary

    The text announces CVE‑2026‑5305, a stored XSS flaw in the Email Address Encoder WordPress plugin prior to version 1.0.25, and links to a detail page but offers no information on exploits, patches or in‑the‑wild activity.

    00000115
    4.1K followersView on X

Explore more